Consultant –GRC
CPX · Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeThe Consultant – Cyber Consulting Services is responsible for supporting the delivery, implementation, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. Working under the guidance of senior consultants and the engagement lead, the role holder executes assigned GRC and Information Security tasks, contributes to the development and maintenance of policies, risk assessments, compliance activities, and audit support, and helps improve the Information Security maturity of the organization and its wider regulated sector. Operating within a healthcare regulatory environment, the role requires alignment of day-to-day deliverables with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements.
Key Responsibilities
-Support the development, implementation, and maintenance of Information Security policies, standards, procedures, guidelines, and templates for the organization and its regulated sector, aligned to legal, regulatory, and international best practices, including the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and ISO/IEC 27001.Execute assigned compliance management activities and assessments under guidance; help gather evidence, assess operational capabilities, and document compliance and control effectiveness levels against applicable standards and regulatory requirements.Support the Information Security Risk Management Program for the organization and its regulated sector by conducting risk assessments, maintaining risk registers, and tracking treatment actions under the direction of senior consultants, helping manage Information Assurance, Information Security, and Cyber Security risks.Support internal and external Information Security audits and assessments for the organization and its regulated sector by preparing documentation, collating evidence, and tracking findings through to closure under the guidance of senior consultants.Support coordination with internal business functions, sector stakeholders, and regulatory bodies on Information Security matters, deviations, exemptions, and incidents, ensuring timely and accurate follow-up on assigned actions.Support awareness, training, and outreach activities; prepare and maintain accurate GRC documentation, trackers, and reports; and report progress, deviations, and issues on assigned tasks to senior consultants and the engagement lead.Skills/Certifications (Technical & Non-Technical) : -Working understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with the ability to execute assigned tasks accurately under guidance. Working knowledge of, or demonstrable exposure to, the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard, together with familiarity with UAE healthcare regulatory and information security requirements, is required. Preferred certifications: ISO/IEC 27001 Lead Implementer or Lead Auditor; Certified in Risk and Information Systems Control (CRISC); Certified Information Systems Auditor (CISA); Certified Information Systems Security Professional (CISSP) or equivalent. Foundational certifications (e.g., ISO/IEC 27001 Foundation, CompTIA Security+) are advantageous.Risk-Based Thinking; Policy and Documentation; Analytical Skills; Time and Task Management; Stakeholder Communication; Team Collaboration; Attention to Detail; Willingness to Learn; Integrity and Confidentiality.Minimum Work Experience & Education : -Minimum of 5 years of experience in governance, risk, compliance, and Information Security, including exposure to cybersecurity, technology risk, regulatory compliance, or audit support activities. A demonstrable portion of this experience should be within the UAE healthcare sector or a healthcare regulatory environment, with hands-on exposure to implementing, assessing, or supporting compliance against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field.